<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>PocketMine-MP (&lt; 4.7.2) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/pocketmine-mp--4.7.2/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 06 Sep 2026 12:45:39 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/pocketmine-mp--4.7.2/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Denial of Service Vulnerability in PocketMine-MP</title><link>https://feed.craftedsignal.io/briefs/2026-09-pocketmine-dos/</link><pubDate>Sun, 06 Sep 2026 12:45:39 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-pocketmine-dos/</guid><description>PocketMine-MP versions prior to 4.7.2 are vulnerable to a denial-of-service attack due to improper exception handling when parsing skin geometry data.</description><content:encoded><![CDATA[<p>PocketMine-MP versions prior to 4.7.2 contain a vulnerability in the handling of skin geometry data parsed via the adhocore/json-comment library. The issue arises from the application's failure to properly handle exceptions triggered during the parsing of malformed or invalid JSON input within skin geometry packets. An unauthenticated attacker can exploit this by sending specially crafted login or skin packets containing invalid JSON structure. When the application attempts to parse this data, it triggers an unhandled RuntimeException, which leads to an immediate server crash, resulting in a denial-of-service (DoS) condition. This vulnerability (CVE-2022-51009) is significant because it allows remote, unauthenticated attackers to disrupt server availability by sending malicious packets. Defenders should prioritize patching to version 4.7.2 or later to mitigate this risk.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability results in an immediate service crash, rendering the Minecraft server instance unavailable to legitimate players. This denial-of-service condition directly impacts availability for all hosted game instances running affected versions of PocketMine-MP, requiring manual intervention by administrators to restore service.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Patch the PocketMine-MP software to version 4.7.2 or later immediately to address CVE-2022-51009.</li>
<li>Monitor game server process logs for repeated runtime exceptions or sudden termination signals that coincide with login or player skin update activity.</li>
<li>Review perimeter and server-side traffic logs for spikes in malformed packets targeting the Minecraft game protocol port.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>denial-of-service</category><category>vulnerability</category><category>game-server</category></item></channel></rss>